- Supply Shock
- Posts
- đ± 17,000 BTC lost
đ± 17,000 BTC lost
When a major exchange accidentally deleted its private keys

When it comes to Bitcoin mantras, ânot your keys, not your coinsâ is as pure as it gets.
But there are levels to it. Sure, you might be self-custodying, but you might still be required to trust a wallet explorer, for example, to tell you your BTC balance.
Run your own full node, however, and youâll only ever need to trust your own copy of the Bitcoin ledger.
Todayâs edition is one of Bitcoinâs oldest cautionary tales about why the above still matters, a decade and a half later.
Itâs also the last time that youâll hear from us on a Friday, for a while. Weâre shifting into low-power mode temporarily, which means youâll only see us in your inbox on Tuesdays and Thursdays.
For now, enjoy the weekend!

Itâs mid-2011, and there are two major exchanges to buy and sell bitcoin: Mt. Gox, operating out of Japan with about 80% global market share, followed by TradeHill, based in California.
Eastern Europe had its own primary venue: Bitomat from Poland.
Bitomatâs trading volume was small compared to Mt. Gox, only about 17,000 BTC per month â far below Mt. Goxâs 1 million BTC (worth $7.5 million at the time). But it was still enough for Bitomat to be considered the third-largest bitcoin trading platform in the world.
Until trouble struck.
On August 1, 2011, Bitomatâs admins disclosed the worst had happened: They had accidentally deleted the wallet.dat file for the platformâs hot wallet, immediately losing access to its users' bitcoin, which coincidentally amounted to 17,000 BTC.
The exchange itself had been paused for about a week by that point. Bitomatâs administrator, Bartek Szabat, had noticed that the main server â powered by an Amazon EC2 virtual machine â had been running at full capacity, and opted to boost its allocation of RAM.
That wouldâve required the virtual machine instance to be rebooted.
But the admin had forgotten to enable persistent storage in the cloud serverâs configuration settings. So, when the server was rebooted after adding more RAM, the local storage of the virtual machine instance itself, which contained the exchangeâs only wallet.dat file, was wiped, taking the private keys of Bitomatâs users along with it.
Amazon Web Services was unable to recover the file.
In an open letter to the Bitcoin community, Szabat asked for help in investigating the situation (the post has been automatically translated and edited for clarity):
âAt the moment, I am unable to clearly determine the cause of crashes. I suppose that it is the result of actions of third parties, which are causing the server to crash to hide their illegal activities, or intentionally wanting the website to disappear,â he wrote.
âIf my suspicions are confirmed, I will tell the police and prosecutors, [and] at the same time, take possible action through which it would be possible to recreate lost data. But I need to interact with the server's owner [Amazon Web Services], and that, as I mentioned above, is difficultâŠâ
âAt the same time, I am counting on your help in solving the problem. I realize that the situation is very difficult, and you fear for the fate of your BTC. We are constantly working on a solution to the crisis, and I'm open to your suggestions.â

Hacker News users had the right idea in July 2011 â only keep bitcoin in exchanges for as long as you need to
Szabat then offered to sell Bitomat the euro equivalent of 17,000 BTC ($220,000 then, $1.95 billion today), in an overt effort to make users whole.
âI wish to inform you that I had several conversations with potential investors from home and abroad,â he said, and directed anyone interested to reach out via email.
It was actually Mark Karpeles and Mt. Gox that answered the call. The deal meant Bitomat would shut down altogether and its domain would instead forward existing users to a Polish-language localized version of Mt. Gox, where they could log in as normal and trade bitcoin via a new Polish zĆoty pair.
âThe acquisition of Bitomat.pl is a windfall for its users, especially in the wake of such a sudden and unsettling event. Also, for the first time ever on a bitcoin exchange, users are now able to access a substantially larger market with their local currency, so we think itâs a happy ending all around,â Karpeles said at the time.
Mt. Gox had only months earlier suffered through two of its many hacking incidents, one for 80,000 BTC ($~65,000) when a thief was able to copy the platformâs own wallet.dat file, and another for 300,000 BTC ($~1.5 million) two months later, with the hacker eventually returning all but 3,000 of the stolen coins.
Of course, Mt. Gox would go completely belly-up nearly three years later, potentially affecting any Bitomat users who had migrated over for a second time.
Thereâs no question that modern day crypto exchanges, at least the top-tier ones, are different beasts compared to the earliest platforms like Bitomat and Mt. Gox. But for all their assurances, we can never really know for sure how well exchanges are storing user bitcoin.
This is both the coolest and hardest part of using Bitcoin: It takes trust to trade bitcoin and significant operational security to store it yourself (although multi-sigs do help). Anything else is just managing exposure.
If it were easy, everyone would do it. Until then, in exchanges we trust.
â David
Institutional interest in Ethereum is running hot. ETF flows are gaining momentum, new token acquisition vehicles are forming every week, and ecosystem morale is nearing ATHs.
The only question left: Where will $ETH be when DAS London kicks off this October?
đ October 13-15 | London

BTC/USD fell to three-week lows of $114,145 this morning but has since recovered above $115,800.
Strategy reported $10 billion profit in Q2 largely due to appreciation of its BTC holdings. Revenue rose 3% YoY to $114.5 million.
ICYMI: Blockstream has rolled out a new smart contract programming language for its Liquid sidechain, Simplicity, which was first proposed in 2012.